Updated: 28 September 2026
This policy explains the personal data used to run PartyStream.Tv, why it is used, who may receive it and how you can exercise your rights. It covers visitors, Guestlist applicants, ordinary users, partners, buyers and people appearing in content.
1. Who is responsible
Daniel Barančík operates PartyStream.Tv and is the controller for the platform's own processing of personal data. For privacy matters, contact support@partystream.tv.
Privacy requests can be sent to support@partystream.tv or through Contact. State which account or content your request concerns, but do not email passwords, authentication codes or a full identity document unless a necessary, secure verification procedure has first been agreed.
A partner who independently organises an event, sells a product or provides a booked service may separately control the data needed to fulfil that transaction. Facebook, Instagram and other external services also have their own responsibilities and notices. Their role does not remove PartyStream's obligations for its own processing.
2. Accounts, preferences and support
We process account identifiers, username, email address, password hash, selected language, profile information and images you provide, social links, account status and relevant support communications. Optional profile fields are not all required to open an ordinary account. Browser language can select the initial language; your chosen preference can then be retained.
The purpose is to create and operate your account, provide requested features and answer you. The principal basis is performance of the service contract or steps you request before entering it (GDPR Article 6(1)(b)); security and abuse prevention may additionally rely on proportionate legitimate interests (Article 6(1)(f)). Marketing, where introduced, needs its own applicable basis and controls; creating an account is not blanket marketing consent.
3. Guestlist and Interview applications
Daniel Barančík reviews your application to identify beta testers and prevent fake accounts. Your answers, photo and social profile are private, not a public profile. Fields marked as required are needed for this review. Questions or data requests: support@partystream.tv.
We use your name and email to handle your request and send the decision or invitation, as steps you request before opening an account (GDPR Article 6(1)(b)). Manual checking of your photo, answers and the public parts of the social profile you supply, and protection against abuse, rely on our legitimate interest in identifying beta testers and preventing impersonation (Article 6(1)(f)). A person decides; we do not use AI scoring or facial recognition for Interview.
You can submit an application without a photo. Send only your own photo and profile. Do not send identity documents, passwords, medical information or other sensitive details. The photo and profile help with manual identification; they are not official identity or age verification. Interview does not grant partner status or 18+ access. Without the required information we cannot assess the application; contact support if you cannot provide it or object to this processing.
Access is limited to authorised reviewers and providers needed for hosting, email delivery and security. Interview does not publish your data, add you to marketing lists or send your answers to an AI service. Cloudflare Turnstile, when enabled, processes browser and network signals for bot protection; Cloudflare also uses those signals to improve detection. The Privacy Policy explains recipients and transfers outside the EEA. Technical session storage supports the requested forms and security.
Unreviewed applications are eligible for daily cleanup after 30 days from submission; approved or rejected applications after 90 days from the decision. Cleanup covers answers, private photos, this notice record and decision-email history. Pending email delivery can delay cleanup until its bounded attempts finish. Server logs and protected backups have separate retention, described in the Privacy Policy. An approved account has its own retention rules.
You can request access, correction, erasure or restriction, and portability where applicable; you can object to legitimate-interest processing. Contact support@partystream.tv to withdraw your application or exercise these rights. We normally respond within one month. You may complain to the Slovak data protection authority or another competent authority. Confirming that you have read this information is not consent to marketing, biometrics or unrelated processing.
4. Community, media and transactions
We process uploads, broadcasts, thumbnails, previews, recordings where enabled, titles and metadata, comments, reactions, follows, playlists, watch history, chat and messenger content, attachments and delivery information. These data support the features you use and, where relevant, reporting, moderation, recommendations and abuse prevention.
For events, tickets, merchandise, paid access, fanclubs, tips, gifts and bookings, records may include the parties, offer, amount, token movement, status, order and payment references, attendance or ticket scans, delivery/contact details, refund requests, dispute evidence and communications. Test-token transactions are also recorded but are not evidence that a real payment occurred.
Contract performance is the main basis for supplying requested transactions. Legal obligations may require retention of real financial or accounting records (Article 6(1)(c)); fraud prevention and defending claims may rely on legitimate interests. Sellers, organisers and providers receive the information reasonably needed to fulfil the relevant transaction, not unrestricted access to your whole account.
5. Identity and age verification through Didit
When you start verification, PartyStream sends Didit a verification reference linked to your account, the selected workflow, callback information, email and language, IP address and existing first/last name where available. The Didit flow can collect identity-document images and details, a selfie or liveness recording and face-comparison data, according to the checks shown to you.
PartyStream retrieves the decision and uses verification status, session references, timing and verified name/age information. The current integration records the outcome and account-verification metadata; it does not copy identity-document images or selfies into your public profile. Authorised personnel may nevertheless have access to verification evidence through Didit's service when needed for review.
Verification supports account authenticity, partner admission, adult access and fraud prevention. Processing ordinary identity data requires a basis under Article 6 GDPR. Biometric data used for unique identification additionally require a condition under Article 9, such as explicit consent where applicable. General agreement to these Terms or this notice is not that consent; read the separate information shown in the verification process.
Didit provides the verification service. Verification records have their own retention rules; approval does not mean immediate deletion. Contact support@partystream.tv for information about your verification data, to challenge a result or to request access or erasure. These requests also cover data held by the verification provider, subject to applicable retention obligations.
The minimum age for an ordinary account is 16 under the Terms, without a routine identity-document check solely for that account. Access to content marked 18+ requires an approved Didit result establishing adulthood. Identity verification, adult-access eligibility and partner status are separate data; none certifies permission to publish a particular work.
6. Who can see your content
Visibility depends on the feature and chosen audience. Public profile fields, social links, public posts, comments, reactions, live chat and participation can be seen by other users. Broadcasts, enabled OBS overlays and promotional media may show profile names, avatars, chat contributions or gifts. A private message is intended for its participants, but it is not represented as end-to-end encrypted against the service operator.
We and authorised providers may process communications for delivery and storage, and access relevant material where necessary for support, security, reports or legal requirements. A recipient can independently save or share material; technical access controls cannot guarantee that no copy will ever be made.
Recording settings govern full-stream recording. Operational thumbnails and previews may still be generated, and Share Studio can capture a short promotional source when requested. Do not include people or private surroundings without an appropriate basis. People appearing in content can contact us about their data even if they do not have an account.
7. Share Studio, OpenAI and Meta
Share Studio processes the selected live moment, available profile and stream information, public chat elements and promotional assets. For requested caption generation, the relevant prompt, context and any image used by that feature are sent to the OpenAI API. When a viewer requests a chat translation, the selected message and target language are sent to OpenAI; names or other personal data may be present in the message. Interview answers and photos are not sent to AI services. Review AI-generated results: they can be inaccurate.
When you authorise publishing, selected assets, captions and appropriate tags or collaboration information are sent to Meta for PartyStream's connected Facebook Page or Instagram account. The platform stores publishing identifiers, status, errors and links so you can follow the result. Publishing on a connected platform account is not the same as giving PartyStream access to your personal social inbox.
These operations support the feature you request. Do not supply sensitive material unnecessarily, and review generated captions and proposed mentions. Meta processes publications under its own terms. External copies and resharing may persist after a local asset is removed. Provider retention and use of data depend on the relevant service and processing arrangements; contact support for information or requests concerning your data.
8. Security, location and recommendations
We process IP addresses, user-agent/browser and device information, session and recognised-device identifiers, authentication and two-factor events, security reports, relevant request logs and error diagnostics to protect accounts and keep the service functioning. Cloudflare security checks, including Turnstile where enabled, may process technical challenge data.
Approximate location can be derived server-side from an IP address using a GeoLite2 database. This is not a claim to know your exact GPS position. Location you explicitly add to a profile, event or booking is separate.
Recommendations can use follows, views, reactions, content characteristics and interests. This is automated personalisation, not a claim that the service uses no algorithms. Security checks and Didit results can restrict particular functions. Contact support to challenge an incorrect restriction and request human review where applicable.
9. Recipients and international transfers
- Hosting, media and delivery: server infrastructure, Bunny for storage/CDN delivery and Cloudflare for web delivery and security receive the technical or content data needed for those functions.
- Media processing: local or dedicated processing and Runpod, where selected for a media job, process the source media and output needed for conversion. Jobs do not require an unrelated copy of your entire account.
- Verification: Didit processes the verification information described above.
- AI and publishing: OpenAI and Meta receive the data needed for requested Share Studio operations.
- Messaging and transactions: email delivery providers, selected sign-in providers and payment providers receive data for the corresponding enabled function. A payment provider is not used merely because a play-token balance is displayed.
- Other recipients: a transaction's seller, organiser or service provider, authorised advisers, and authorities where disclosure is required or otherwise lawfully justified.
Some providers, support teams or subprocessors may process data outside the European Economic Area. Such transfers require an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses and any necessary supplementary measures. Using this website is not blanket consent to unrestricted international transfers. Contact support for information about the recipients and safeguards applicable to your data.
11. Retention
We should retain data only for a defined service, security, legal or evidential purpose and remove or anonymise it when that purpose ends. Retention is not identical for every data type. Current application settings provide these cleanup periods:
- Interview application retention follows the periods displayed in the application notice: currently 30 days from submission without a decision and 90 days after a decision. Answers, private photos, notice evidence and decision-email history are cleaned up together; email delivery still in progress may postpone cleanup until its limited attempts finish. For the current configured periods, see the notice before submitting an application.
- Share Studio drafts and assets: an expiry of 365 days from creation under the current setting. External publications are not automatically erased by that expiry.
- Session-security events and browser-security reports: 30 days; account-security activity: 180 days.
- Completed security and booking email-outbox history: 30 days under the current settings; delivery and failure handling can affect eligibility.
These are configured application cleanup thresholds, not guarantees that every copy disappears at the exact second. Account data, published content, messages and transaction records have separate purposes; current deactivation does not trigger universal automatic erasure. Validity periods for sessions and verification challenges are separate from historical-log retention.
Real financial records follow applicable accounting, tax and claim-retention periods. A justified dispute or legal hold may require specific records to remain longer. Backup, security-log and provider retention is separate from the application cleanup periods above and depends on recovery, security and legal purposes. Contact support for information about retention or erasure of your particular data.
12. Deactivation, erasure and security measures
Deactivation revokes account access and is not a deletion request. It can preserve content, relationships and financial history needed for other participants. To request erasure, contact support; we will assess deletion, anonymisation and any lawful retention exception rather than silently treating deactivation as erasure.
Security measures include encrypted transport where provided, hashed passwords, access controls, restricted administrative access and session/security protections. No service can promise zero risk. We will handle security incidents and notify affected people or authorities where the law requires. Do not put identity documents or credentials in ordinary chats or public uploads.
13. Your rights
Subject to the applicable conditions, you can request access and a copy, correction, erasure, restriction of processing and data portability. You can object to processing based on legitimate interests and to direct marketing. Where processing is based on consent, you can withdraw that consent without affecting the lawfulness of earlier processing. Some data are necessary for an account, transaction or verified feature, so removing them may prevent that particular service.
Send a request to support@partystream.tv. We may need proportionate proof of identity, but must not demand excessive data. The normal GDPR response period is one month; a lawful extension for complex or numerous requests must be explained within that month. A refusal or limitation must be explained together with available remedies.
You may complain to the Office for Personal Data Protection of the Slovak Republic or another competent supervisory authority, including in the EU country where you live or work. You do not have to give up that right by first accepting an internal decision.
14. Age, changes and further information
Ordinary accounts are intended for people aged 16 or over, including 16- and 17-year-olds using age-appropriate functions. We do not require every ordinary user to provide an identity document just to satisfy this contractual minimum. Content marked 18+ is separately restricted through adult verification. Contact us if an under-16 account or inappropriate access is suspected.
Data relating to minors warrant particular care. Do not post unnecessary sensitive information about a child. A parent or guardian may contact us about a young person's data, subject to appropriate checks of their authority and the young person's own rights. Ordinary account access is not a blanket authorisation for paid contracts or special-category data processing.
We will update this notice when material processing changes and provide any notice or new consent required by law. A change cannot retroactively create consent for a different purpose. The date above identifies the current version. Questions about this notice can be sent to support@partystream.tv.